Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.064exploits catalogados
37.667CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9.080Nuclei 4.432Metasploit 3.505✓ só verificadosrecentespopularesrisco
80.930 exploits
GitHub PoC★ 1
CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1
Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
63RISCO
abrir ↗VulnCheck XDB
local
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir ↗VulnCheck XDB
initial-access
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir ↗GitHub PoC★ 8
New vulnerability found in Docker. Credit for finding the vulnerability goes to Felix Boulet
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir ↗VulnCheck XDB
local
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir ↗GitHub PoC★ 11
b0ySie7e/CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC
This repository provides a modified version of the original CVE-2017-6074 exploit (use-after-free in the Linux kernel DCCP subsystem), designed only to demonstrate Denial of Service (DoS) impact. An authenticated local user can trigger a kernel panic, causing a total loss of system availability.
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISCO
abrir ↗GitHub PoC
This is a PoC for the CVE-2025-24813 and tested in different environments.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC★ 1
This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln
DOMPurify nesting-based mXSS
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISCO
abrir ↗VulnCheck XDB
initial-access
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISCO
abrir ↗GitHub PoC★ 2
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir ↗GitHub PoC
Python3 port of the original Joomla Core (1.5.0 through 3.9.4) - Directory Traversal && Authenticated Arbitrary File Deletion
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RISCO
abrir ↗GitHub PoC★ 1
jsnv-dev/CVE-2024-51568---CyberPanel-Command-Injection-Nuclei-Template
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISCO
abrir ↗GitHub PoC★ 1
Version detection PowerShell
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISCO
abrir ↗VulnCheck XDB
infoleak
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir ↗VulnCheck XDB
initial-access
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
85RISCO
abrir ↗VulnCheck XDB
initial-access
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir ↗VulnCheck XDB
initial-access
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISCO
abrir ↗VulnCheck XDB
initial-access
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RISCO
abrir ↗VulnCheck XDB
initial-access
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir ↗VulnCheck XDB
initial-access
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RISCO
abrir ↗GitHub PoC★ 1
a proof of concept of CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗VulnCheck XDB
initial-access
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC★ 1
Sawtooth Lighthouse Studio存在模板注入漏洞CVE-2025-34300
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
85RISCO
abrir ↗GitHub PoC★ 1
HTML cache poisoning through unsafe reflections
HTML Cache Poisoning through Unsafe Reflections
53RISCO
abrir ↗GitHub PoC★ 7
FreePBX SQL Injection Exploit
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.